Use-after-free vulnerability in the FrameView::calculateScrollbarModesForLayout function in page/FrameView.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that calls the removeChild method during interaction with a FRAME element.
References
Configurations
History
21 Nov 2024, 01:27
Type | Values Removed | Values Added |
---|---|---|
References | () http://crbug.com/79055 - | |
References | () http://launchpad.net/bugs/778822 - | |
References | () http://trac.webkit.org/changeset/84300 - |
07 Nov 2023, 02:07
Type | Values Removed | Values Added |
---|---|---|
References | () http://crbug.com/79055 - | |
References | () http://launchpad.net/bugs/778822 - | |
References | () http://trac.webkit.org/changeset/84300 - |
Information
Published : 2014-12-26 02:59
Updated : 2024-11-21 01:27
NVD link : CVE-2011-1796
Mitre link : CVE-2011-1796
CVE.ORG link : CVE-2011-1796
JSON object : View
Products Affected
- chrome
CWE